Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
327 results
CVE-2026-18963 preview

CVE-2026-18963

GitHubalt3kx/cve-2026-18963

Detection and verification tool for CVE-2026-18963, a Keycloak reset-credentials state bypass. Performs version fingerprinting, realm/client/user…

authenticationexploitationinformation-gathering+4
6 days ago
CVE-2026-41940-AuthBypass-Detector preview

CVE-2026-41940-AuthBypass-Detector

GitHubunteikyou/cve-2026-41940-authbypass-detector

Detection tool for cPanel/WHM CVE-2026-41940 (CRLF injection auth bypass). Verify vulnerability on servers you own or have permission to test. For…

authenticationpenetration-testingreconnaissance+2
24 months ago
CVE-2026-26128 preview

CVE-2026-26128

GitHubjarnovandenbrink/cve-2026-26128

Exploits Kerberos reflection via Unicode normalization in Windows Active Directory to relay authentication to ADCS and MSSQL, enabling…

authenticationexploitationpenetration-testing+2
633 months ago
poc-cpanel-cve-2026-41940 preview

poc-cpanel-cve-2026-41940

GitHubxsanflip/poc-cpanel-cve-2026-41940

Multi-threaded security auditing tool that detects CVE-2026-41940, an authentication bypass in cPanel/WHM, using CRLF injection and dynamic port…

authenticationexploitationinformation-gathering+3
644 months ago
CVE-2026-24061-GNU-Inetutils-telnetd-Remote-Authentication-Bypass-Root-Shell- preview

CVE-2026-24061-GNU-Inetutils-telnetd-Remote-Authentication-Bypass-Root-Shell-

GitHubmbanyamer/cve-2026-24061-gnu-inetutils-telnetd-remote-authentication-bypass-root-shell-

Proof-of-concept exploit for GNU Inetutils telnetd authentication bypass (CVE-2026-24061) that spawns a root shell via crafted NEW-ENVIRON USER…

authenticationexploitationpenetration-testing+3
6 months ago
CVE-2026-31816-rshell preview

CVE-2026-31816-rshell

GitHubimjdl/cve-2026-31816-rshell

Exploits CVE-2026-31816 in Budibase to bypass authentication, upload a malicious datasource plugin, and execute a reverse shell for remote access.

authenticationexploitationpayload-development+2
5 months ago
cPanel-WHM-AuthBypass-Session-Checker preview

cPanel-WHM-AuthBypass-Session-Checker

GitHubdebugactiveprocess/cpanel-whm-authbypass-session-checker

Validates injected sessions from the CVE-2026-41940 cPanel/WHM authentication bypass exploit, testing endpoints to distinguish patched servers from…

authenticationexploitationpenetration-testing+3
74 months ago
CVE-2026-29000 preview

CVE-2026-29000

GitHubcipher1x1/cve-2026-29000

Proof-of-concept exploit for CVE-2026-29000, an authentication bypass in pac4j-jwt via JWE-wrapped unsigned JWT, enabling privilege escalation.

authenticationexploitationpenetration-testing+2
4 months ago
CVE-2026-1529-PoC-keycloak-unauthorized-registration-via-improper-invitation-token-validation preview

CVE-2026-1529-PoC-keycloak-unauthorized-registration-via-improper-invitation-token-validation

GitHubackemed/cve-2026-1529-poc-keycloak-unauthorized-registration-via-improper-invitation-token-validation

Exploit tool for CVE-2026-1529, demonstrating unauthorized organization registration in Keycloak via JWT token manipulation. Includes token…

api-securityauthenticationexploitation+3
6 months ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubparad0x7e/cve-2026-24061

Exploit and scanner for CVE-2026-24061, a telnetd authentication bypass that grants root shell via crafted USER environment variable. Includes Docker…

authenticationexploitationnetwork-security+3
7 months ago
Ashwesker-CVE-2026-24061 preview

Ashwesker-CVE-2026-24061

GitHubmefhika120/ashwesker-cve-2026-24061

Exploit for CVE-2026-24061, a critical remote authentication bypass in GNU InetUtils telnetd, allowing unauthenticated root access via crafted…

authenticationexploitationpenetration-testing+2
7 months ago
CVE-2026-24061 preview

CVE-2026-24061

GitHublucaspdiniz/cve-2026-24061

Vulnerability in GNU InetUtils telnetd Enables Remote Root Access

authenticationexploitationpenetration-testing+2
7 months ago
CPanel-Audit-Remediation-Tool preview

CPanel-Audit-Remediation-Tool

GitHubunderh0st/cpanel-audit-remediation-tool

Audit and incident response tool for CVE-2026-41940 vulnerability

authenticationconfiguration-auditingeducation+3
4 months ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubmonstertsl/cve-2026-24061

Python-based scanner that detects CVE-2026-24061 in GNU Inetutils telnetd, allowing batch testing of multiple targets for the authentication bypass…

authenticationexploitationpenetration-testing+2
17 months ago
GNU-Inetutils-telnet-CVE-2026-24061- preview

GNU-Inetutils-telnet-CVE-2026-24061-

GitHubmy0723/gnu-inetutils-telnet-cve-2026-24061-

GNU Inetutils telnet远程认证绕过漏洞(CVE-2026-24061),该漏洞源于 GNU Inetutils telnetd 组件中对环境变量处理不当,攻击者可利用该漏洞,通过构造恶意的 USER 环境变量并发送至受影响的 telnet…

authenticationexploitationnetwork-security+3
17 months ago
cPanelWHM-AuthBypass preview

cPanelWHM-AuthBypass

GitHubkagantua/cpanelwhm-authbypass

Go-based scanner and exploit tool for CVE-2026-41940, an authentication bypass in cPanel/WHM. Supports batch scanning, token leakage, and…

authenticationexploitationpenetration-testing+3
114 months ago
CVE-2026-41940 preview

CVE-2026-41940

GitHub0xyur1/cve-2026-41940

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

authenticationauthentication-authorizationexploitation+6
103 months ago
CVE-2026-58231 preview

CVE-2026-58231

GitHubwildandeveloper/cve-2026-58231

Non-destructive detection and precondition-verification tool for CVE-2026-58231, probing SAP Commerce Cloud Data Hub endpoints, default OAuth…

api-securityauthenticationinformation-gathering+4
11 days ago
Previous12…19Next